Opens in a new tab
vmblog logo 2024 wht (updated)

Rethinking Privileged Access: Why Legacy Software Is Forcing a New Approach to Least Privilege

Share: 

By David Bellini, CEO at CyberFOX

Every IT security team knows this story. You remove administrator rights from your endpoint computers, knowing you are practicing least privilege. Six months later, you are buried in help desk tickets as AutoCAD will no longer open, QuickBooks will not update, and the engineering and finance team is threatening to escalate the problem.

Least privilege is a good principle. Just give your users the access they need to perform their job, nothing more. This is something Microsoft has recommended for years. Every compliance standard expects it. But here’s what nobody talks about enough: much of the software businesses depend on was built assuming users would have admin rights.

AutoCAD needs elevated rights to write to its license files. Bluebeam requires administrative rights to work with PDF drivers. QuickBooks wants to write to its database with full system rights. These are not niche apps. These are critical business applications used by thousands of companies daily.

IT teams find themselves in an impossible position. Enable admin rights and accept the increased risk of a breach, or disable them and watch productivity collapse. Many organizations have taken the purest approach at least once. Organizations remove all admin rights and commit to the principle, but for weeks after, they receive angry phone calls from the CFO’s office because none of their employees can generate invoices.

The pullback is expected. Administrative rights are restored typically with a vague promise to “revisit this sometime next quarter.” Security teams know a gap exists. Leadership teams know a gap exists. Cyber insurance carriers most certainly know a gap exists. They are the ones questioning the privileged access control during renewal meetings.

The Enterprise PAM Problem

Here’s where it gets worse. The traditional solution to this problem, enterprise privileged access management (PAM) systems, isn’t built for most organizations. These platforms were designed for Fortune 500 companies with dedicated security teams, extensive budgets, and the resources to manage complex deployments. They work fine if you have a full-time PAM administrator, hundreds of thousands of dollars to spend annually, and six months to get everything configured.

Mid-sized companies don’t have those luxuries. Neither do the managed service providers trying to protect hundreds of small business clients. They understand the risk. They know least privilege matters. They just don’t have practical tools that fit their reality.

That’s where the conversation needs to shift. We can’t wait for every software vendor to rewrite decades of lazy code. That’s not happening. And we can’t keep pretending that removing admin rights wholesale is feasible when it breaks critical business functions.

A Smarter Solution for Privileged Access

Wouldn’t it be easier for applications to obtain the appropriate permissions when they need them, rather than for users to maintain administrative login credentials all day? Enter Just-in-time elevation.

Just-in-time elevation is a simple concept. It is based on granting a user the appropriate permissions when an application requires them, and then revoking them after the application completes its task. This means the user does not remain permanently logged into an administrator account, the application has sufficient permissions to complete its task, and the security team retains overall control over the user’s permission levels.

Just-in-time elevation changes the way organizations evaluate the trade-off between functionality and security. Users can run their CAD software or their accounting program as needed, without being a permanent administrator. Help desk personnel receive fewer calls from users requesting access to applications that require administrative-level permissions, and the security team can demonstrate significant improvement in achieving least privilege while continuing to support organizational operations.

This model can be applied to many different industries. For example, manufacturing companies require engineers to utilize CAD software to design new products; however, these engineers don’t need unrestricted administrative permissions. A car dealership may also use specialized financial software that requires its finance staff to have elevated permissions to perform their tasks. School districts manage thousands of endpoints using limited IT personnel, and all share the same basic problem.

While the technical details of implementing just-in-time elevation are important, the most critical component is changing your perspective. Don’t continue to view least privilege as an either/or proposition. Start viewing privilege as something that can be granted temporarily and only when absolutely required.

Making It Practical

Automation is what makes this a viable option. Organizations will need systems that can identify trusted applications, grant necessary access, log activities for auditing, and revoke access once an application session ends, all without continuous human intervention.

For organizations evaluating and/or developing a privileged access strategy, there are many factors to consider:

Start with visibility. Before controlling who has admin rights, organizations need to know which applications currently require admin rights and why. Run your environment in audit mode. Watch what breaks when you restrict access. Build a complete inventory of privilege dependencies.

Test incrementally. Don’t implement new access controls and assume they will work correctly. Select one department or application category and implement access controls for it. Measure results. Adjust as needed. Then expand to additional departments.

Set clear policies for what constitutes legitimate elevation needs. Not every app that requests admin rights truly needs them. Developers may have requested elevated permissions simply because it was easier than determining the minimum required access.

Make sure whatever approach you choose includes real logging and reporting. Auditors will ask for proof that you’re controlling privileged access. Cyber insurance carriers will want evidence. Boards will eventually want to know if security posture has improved.

Looking Ahead

The stakes keep rising. Ransomware operators specifically target admin credentials because that’s how they move laterally through networks and deploy payloads. Cyber insurance premiums reflect the risk of poor access controls. Compliance frameworks become increasingly specific each year about how organizations must manage privileged access.

But business reality hasn’t changed. Companies still need their applications to work. Users still need to do their jobs. IT teams still face resource constraints that make enterprise-grade PAM platforms impractical.

That gap is where innovation needs to happen. Not in creating more complex systems that only the largest organizations can implement. In building practical solutions that let companies of all sizes implement least privilege without breaking their operations or budgets.

We’ve spent 30 years telling organizations they should remove admin rights. It’s time to give them tools that make it actually possible.

##

ABOUT THE AUTHOR

David Bellini Photo

David is a co-founder and the Chief Executive Officer for CyberFOX. Serving as the Chief Operating Officer and working with his brother Arnie Bellini, the duo spun the ConnectWise software company out of their Tampa-based IT service provider more than four decades ago. David most recently served as the President of International Sales and Operations where he spearheaded and managed the international expansion for ConnectWise. David was a major contributor in the private equity firm Thoma Bravo acquiring ConnectWise in 2019.